imPC@ndo EN

Vulnerabilità Citrix

393 CVE

CVE-2018-17444
Alta 7.5

A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

citrix netscaler_sd-wan · citrix sd-wan
0.04EPSS
CVE-2017-2620
Media 5.5

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw t…

citrix xenserver · debian debian_linux · qemu qemu · redhat enterprise_linux_desktop · e altri 6
0.04EPSS
CVE-2020-8270
Alta 8.8

An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342

citrix virtual_apps_and_desktops
0.03EPSS
CVE-2016-2071
Critica 9.8

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands.

citrix netscaler
0.03EPSS
CVE-2017-5933
Media 5.9

Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GCM nonces, which makes it marginally easier for remote attackers to obtain the GCM authentication key and spoof …

citrix netscaler_application_delivery_controller_firmware
0.03EPSS
CVE-2016-9679
Critica 9.8

Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.

citrix provisioning_services
0.03EPSS
CVE-2015-5538
Alta 10.0

Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allow remote attackers to gain privileges via unknown vectors…

citrix netscaler_application_delivery_controller_firmware · citrix netscaler_gateway_firmware
0.03EPSS
CVE-2018-6186
Alta 8.8

Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges.

citrix netscaler
0.03EPSS
CVE-2016-9678
Critica 9.8

Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

citrix provisioning_services
0.03EPSS
CVE-2020-8300
Media 6.5

Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note …

citrix application_delivery_controller_firmware · citrix gateway · citrix netscaler_gateway
0.03EPSS
CVE-2014-1664
Media 5.0

The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain user IDs, meeting details, and authentication tokens via an application that reads the system log file.

citrix gotomeeting
0.03EPSS
CVE-2018-18013
Alta 7.8

* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a …

citrix xenmobile_server
0.03EPSS
CVE-2015-2838
Media 6.8

Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators for requests that execute arbitrary commands as nsroot via shell metacharacters in …

citrix netscaler
0.03EPSS
CVE-2018-5314
Alta 7.5

Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 500…

citrix netscaler_application_delivery_controller · citrix netscaler_gateway · citrix netscaler_sd-wan
0.03EPSS
CVE-2007-2850
Alta 10.0

The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address…

citrix access_essentials · citrix metaframe
0.03EPSS
CVE-2023-3466
Alta 8.3

Reflected Cross-Site Scripting (XSS)

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.03EPSS
CVE-2009-3760
Alta 7.5

Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these…

citrix xencenterweb
0.03EPSS
CVE-2008-2528
Alta 10.0

Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified vectors.

citrix access_gateway
0.03EPSS
CVE-2020-8269
Alta 8.8

An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9

citrix virtual_apps_and_desktops · citrix xenapp · citrix xendesktop
0.03EPSS
CVE-2013-2757
Alta 7.5

Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network, which allows remote attackers to have unspecified impact via unknown vectors.

citrix cloudplatform
0.03EPSS
CVE-2020-10110
Media 5.3

Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and…

citrix gateway_firmware
0.03EPSS
CVE-2021-44519
Alta 8.8

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.

citrix xenmobile_server
0.03EPSS
CVE-2014-3780
Alta 7.5

Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to bypass authentication via unspecified vectors, related to a Java servlet.

citrix vdi-in-a-box
0.03EPSS
CVE-2018-18571
Critica 9.1

An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled…

citrix xenmobile_server
0.03EPSS
CVE-2020-8283
Alta 8.8

An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.

citrix virtual_apps_and_desktops · citrix xenapp · citrix xendesktop
0.03EPSS